← Back to sign in

Privacy Policy

NovaLite · Operated by Zerdium · Effective: 27 July 2026

This Privacy Policy explains how Zerdium (“we”, “us”) processes information when you use the NovaLite remote support and administration platform (the “Service”). It is intended for authorized operators and administrators of this hosted instance.

1. Controller

The Operator of this instance is Zerdium. For privacy questions, contact support via t.me/zerdiums.

2. Categories of data

  • Account data — username, password hash, role, permissions, optional MFA settings.
  • Authentication & security — session tokens/cookies, IP address, user agent, login audit events.
  • Operational data — enrolled device inventory (hostname, OS, hardware summary), connection status, build metadata, feature usage logs.
  • Session content — remote desktop frames, file transfer content, console output, and similar data generated when you use a feature (processed to deliver that feature).
  • Support data — messages you send through support channels.

3. Purposes and legal bases

We process data to:

  • Authenticate users and protect the Service (legitimate interest / contract);
  • Provide remote support and device-management features you request (contract / legitimate interest);
  • Maintain security, audit trails, abuse prevention, and service integrity (legitimate interest / legal obligation where applicable);
  • Improve reliability and diagnose faults (legitimate interest).

Where local law requires consent for monitoring or remote access on end-user devices, the organization deploying Agents is responsible for obtaining that consent.

4. Edge networks and Cloudflare

Traffic to the Service may pass through reverse proxies, CDNs, and security services such as Cloudflare for TLS, DDoS protection, caching of static assets, and bot management. Those providers may process IP addresses, request metadata, and security signals according to their own terms and privacy notices. We configure edge services only as needed to operate and protect the Service.

5. Retention

Account data is retained while the account remains active. Logs and operational records are kept for a period necessary for security, debugging, and service administration, then deleted or anonymized. Session media is generally ephemeral unless you deliberately save or record it using a feature that stores artifacts.

6. Sharing

We do not sell personal data. We may share data with infrastructure providers (hosting, CDN, DNS, email, TURN/media relays) under contracts that limit use to providing the Service, or when required by law, or to protect rights, safety, and security.

7. International transfers

Depending on hosting and edge configuration, data may be processed in multiple regions. Where required, appropriate safeguards are applied for cross-border transfers.

8. Security

We use industry-standard measures such as encrypted transport (HTTPS/WSS), access control, session management, and optional multi-factor authentication. No method of transmission or storage is 100% secure; you must protect endpoints and credentials under your control.

9. Your rights

Subject to applicable law, you may request access, correction, deletion, or restriction of personal data we hold about you, or object to certain processing. Contact support to exercise rights. Some requests may be limited where we must retain data for security or legal reasons.

10. Children

The Service is not directed to children under 16 (or higher age required by local law). We do not knowingly collect data from children.

11. Changes

We may update this Policy by publishing a new version with a revised effective date. Continued use of the Service after changes constitutes acceptance where permitted by law.

12. Contact

Zerdium — NovaLite privacy inquiries:
t.me/zerdiums
Urgent / law-enforcement / DCAM or other takedown notices: [email protected]

Related: Terms of Service · Cookie Notice